CVE-2025-8735

Name
CVE-2025-8735
Description
A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
exploit https://drive.google.com/file/d/1Q_rDQSEl3cBu6SUbfqr9pV9cHgvKcXFI/view?usp=drive_link
related https://lists.gnu.org/archive/html/bug-cflow/2025-07/msg00000.html
signature https://vuldb.com/?ctiid.319231
vdb-entry https://vuldb.com/?id.319231
third-party-advisory https://vuldb.com/?submit.622328
product https://www.gnu.org/
af854a3a-2127-422b-91ae-364da2661108 https://www.openwall.com/lists/oss-security/2025/10/27/12

Match rules

CPE URI Source package Min version Max version
cflow == 1.0 == 1.0
cflow == 1.1 == 1.1
cflow == 1.2 == 1.2
cflow == 1.3 == 1.3
cflow == 1.4 == 1.4
cflow == 1.5 == 1.5
cflow == 1.6 == 1.6
cflow == 1.7 == 1.7
cflow == 1.8 == 1.8

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
cflow edge-community 1.8-r0 qaqland <qaq@qaq.land> possibly vulnerable
cflow edge-community 1.7-r1 qaqland <qaq@qaq.land> possibly vulnerable
cflow edge-community 1.7-r0 qaqland <qaq@qaq.land> possibly vulnerable
cflow 3.22-community 1.7-r0 qaqland <qaq@qaq.land> possibly vulnerable